There are vulnerabilities in Java to which the IBM FlashSystem
V840 and FlashSystem V9000 are susceptible (CVE-2017-18017 and CVE-2017-17449). An exploit of CVE-2017-18017 could allow a remote attacker to cause a denial of service condition. An exploit of CVE-2017-17449 could allow an attacker to obtain sensitive information.
CVE(s): CVE-2017-18017, CVE-2017-17449
Affected product(s) and affected version(s):
Storage Node machine type and models (MTMs) affected:
- 9846-AE1 and 9848-AE1
- 9846-AE2 and 9848-AE2
- 9846-AE3 and 9848-AE3
Controller Node MTMs affected:
- 9846-AC0 and 9848-AC0
- 9846-AC1 and 9848-AC1
- 9846-AC2 and 9848-AC2
- 9846-AC3 and 9848-AC3
Supported storage node code versions which are affected
- VRMFs prior to 1.4.8.2
- VRMFs prior to 1.5.2.5
- VRMFs prior to 1.6.1.0
Supported controller node code versions which are affected
· VRMFs prior to 7.8.1.8
· VRMFs prior to 8.1.3.3
· VRMFs prior to 8.2.0.0
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10957179
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/137122
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/136106
The post IBM Security Bulletin: Multiple Vulnerabilities in the Linux kernel affect the IBM FlashSystem models V840 and V9000 appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team https://ift.tt/2MANPto
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.